ljg-travel

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the workflow expands into a multi-skill pipeline that consumes large volumes of untrusted external content and writes outputs locally without visible guardrails. No direct credential harvesting, exfiltration, or malicious install behavior is present in this skill text, so this is not malware; the main risks are transitive trust and indirect prompt injection.

Confidence: 81%Severity: 56%
Audit Metadata
Analyzed At
Apr 11, 2026, 01:50 AM
Package URL
pkg:socket/skills-sh/yelban%2Fljg-skills.TW%2Fljg-travel%2F@7be920596b98a9ef8d3375511685b03580cb3e55